Tuesday, October 13, 2009

What Is The Zlob Trojan And What Does It Do?

By Jake M. Black

What you need to know about the Zlob Trojan comes down to understanding that, first of all, this is a method that can end up in the placing of a fake anti--spyware program in which the Trojan virus is hidden. What this means, is that a personal computer can end up with a hidden virus that can lead to a lot of issues related to reboots and shutdowns for computers and networks.

Initially, a computer user ends up getting this virus when he or she downloads a codec for a video file and in which the Trojan is hidden. Usually, the Trojan will say that an ActiveX codec is needed. It's in this little piece of code that the Trojan hides and begins its attack upon downloading of that fake ActiveX file.

If the Trojan manages to make it into the computer, what looks to be genuine Microsoft pop-up advisories appear that warn the user that his or her computer is infected with spyware or ad ware and that it should be scanned immediately. Unfortunately, even if a user just tries to close out the pop up it will begin a download of a fake antivirus program that the Trojan needs in order to do its dirty work.

Sometimes the Trojan makes use of an executable file in order to be downloaded, in which case a user might see the icon that MS Windows Security uses and which tends to trick a PC user into thinking that the antivirus file comes from Microsoft and can be used to embed a solution to the problems that the Trojan itself will later cause.

Once that particular file gets in and is installed a large number of problems might begin to occur with the computer, a couple of which revolve around an ordered shutdowns and reboots. In the case of those reboots, the Trojan is causing problems in the Windows Scheduled Tasks files related to an executable file called "zlberfker. Exe". As a result of that particular file, the computer is usually plagued by reboots and shutdowns until a real fix can be implemented.

Another thing that this nasty little Trojan does is set up a redirect program that sends an Internet user to sites that could be fronts for Russian criminal groups in that country who want to try to increase visits to websites they control, including any number of pornographic sites. That can be a nasty shock to people who never use the Internet in such a manner.

A PC user is well advised to never, ever click on a pop up ad that advises that their computer could be infected with spyware or other problems. Instead, when that pop up appears immediately turn off the power to the computer (called a hard shutdown) and then turn it back on and reboot and have the system run a diagnostic check before powering up the operating system.

About the Author:

No comments: